User Name
Password
AppleNova Forums » Apple Products »

How far can hackers get?


Register Members List Calendar Search FAQ Posting Guidelines
How far can hackers get?
Thread Tools
turtle
Lord of the Rant.
Formerly turtle2472
 
Join Date: Mar 2005
Location: Upstate South Carolina
 
2014-04-16, 16:21

So I'm hosting more things from a Lion Server and now starting to put some php based sites up there. While patches and fixes come out, vulnerabilities will always be there with this great game of cat and mouse. As an admin for a hosting company I see most hacks are limited to the cPanel account when exploits are taken advantage of.

With 10.7 and a MAMP stack what is the level of vulnerability? Seems everything is owned by _www so seems that a hacker who might get a shell (example) in might be able to navigate to other sites and compromise them all. Also, what about beyond the site folders? How far will a shell be able to allow them to get?

Does anyone have any experience with this on Mac? I'm very well versed in CentOS and cPanel/WHM, Mac does things a little different though (shocking).

Louis L'Amour, “To make democracy work, we must be a nation of participants, not simply observers. One who does not vote has no right to complain.”
Visit our archived Minecraft world! | Maybe someday I'll proof read, until then deal with it.
  quote
PBMB
Member
 
Join Date: Sep 2010
 
2014-04-24, 03:32

I have no experience or knowledge about the specific questions you ask, but talking about the general issue of how far hackers can go, my guess is very far. Just remember the last big vulnerability discovered. Its name is Heartbleed. It is perhaps the most serious vulnerability from every point of view since a very long time, arguably the most serious ever because no traces that information was accessed are left behind. Scary stuff.
  quote
turtle
Lord of the Rant.
Formerly turtle2472
 
Join Date: Mar 2005
Location: Upstate South Carolina
 
2014-04-25, 18:53

Well, in the world of cPanel/WHM each cPanel account is limited to it's own world. This means if shell access is gained it can't do anything other than impact things owned or accessible to the cPanel user. This is true for Linux in general. Sadly this makes me pretty sure that once a hacker is able to access one site they have access to all sites. Mac is Unix at it's core after all.

Louis L'Amour, “To make democracy work, we must be a nation of participants, not simply observers. One who does not vote has no right to complain.”
Visit our archived Minecraft world! | Maybe someday I'll proof read, until then deal with it.
  quote
Ebby
Subdued and Medicated
 
Join Date: May 2004
Location: Over Yander
Send a message via AIM to Ebby  
2014-04-25, 19:28

I had someone upload a PHP script and start browsing to the root of my drive. No telling what was compromised or if they uploaded/downloaded files. I am hoping permissions saved my toast. That was several system wipes ago so I doubt I have any problems now, but that did tick me off long ago.

Just because your site is small or insignificant doesn't mean you go lax on security

^^ One more quality post from the desk of Ebby. ^^
SSBA | SmockBogger | SporkNET
  quote
Posting Rules Navigation
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Post Reply

Forum Jump
Thread Tools
Similar Threads
Thread Thread Starter Forum Replies Last Post
Apple does "not hate" iPhone hackers ghoti General Discussion 15 2007-09-13 08:29


« Previous Thread | Next Thread »

All times are GMT -5. The time now is 01:48.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004 - 2024, AppleNova